This message was deleted.
# citrix-netscaler
s
This message was deleted.
n
Maybe this is a dumb question, but if this wasn't an issue with the MPX then why is it the VPX? Hypervisors dont have access to the DMZ network or something?
r
Its not dumb Neal, thanks for replying. The DMZ in the hypervisor has no connection to the LAN and the hosting team arent willing to redesign it to help me as apparently it is too much work. So over time i have found all of these things out. Therefore i have said i dont know how to make it work without being a like for like MPX to MPX. So i wondered if anyone here could help me out of a bind because if the F5 is doing it with SNAT and a feature called AutoMap which seems to be some kind of rewrite then id hope the ADC VPX can do it to but i am just unsure.
l
is it a hypervisor specifically for DMZ with only access to DMZ vlans or ? That part is a bit unclear.
If not you could go 2-arm as I'm assuming that is the way the MPX is set up?
nvm, seemed to have missed that part in my first read, you already answered that
r
i believe this is what the F5 is doing but is it possible for the ADC to do it for Ctx GW with MFA for Remote Access? https://support.f5.com/csp/article/K7820#intelligent:~:text=SNAT%20pools.-,Automap%20SNAT,-Of%20the%20available
l
You can RNAT on a netscaler based on an ACL, that would enable you to communicate with a "non-routed" vlan, but you'd still need actual access to that vlan, which from what I understood just isn't there?
Basically you'd create a snip in that vlan, configure an extended ACL (!and apply it, otherwise it won't work!) with the range of source ip's vs range of destination ip's. Afterwards in RNAT you can select this ACL and bind that snip that you created to it. this would ensure that all communication you do to the "non-routed" vlan's servers will originate from the snip that is situated in that vlan, which will allow them to communicate back
r
i have never used RNAT to be honest but any snip other than one from the DMZ wont work because if it uses that SNIP as soon as it hits the DMZ DFG traffic is dropped. I can only send traffic to the DMZ DFG no where else. So LAN traffic has to leave the ADC as a DMZ address 192.168.x.x in disguise to reach the LAN segment. I had this example from the hosting team of how they do it on their appliance as i am being told the firewall will only accept DMZ traffic(192.168.x.x) but i guess i have been struggling as its not my solution or design. But what i dont know is if this can be done on a gw vip with MFA ? Their F5 is just doing load balancing from what i can tell. F5 with a single i/f in the DMZ on 192.168.x.x
So what would a viable working solution be to mask LAN traffic as DMZ for external gateway with MFA, can anyone give me something concrete to run with at all please? These were my original thoughts of enabling L2 mode - https://docs.citrix.com/en-us/citrix-adc/current-release/getting-started-with-citrix[…]figure-system-settings/configure-modes-packet-forwarding.html and using this but as i havent done this i guess i am trying to waste any further time going down dead ends https://docs.citrix.com/en-us/citrix-adc/current-release/load-balancing/load-balancing-manage-clienttraffic/use-specified-srcip.html#:~:tex[…]cation